Junglewise Threat Intelligence

CVE-2024-51316: Tenda TX9 Pro buffer overflow in SetOnlineDevName

CVE-2024-51316 · Severity: info · Published 2026-07-20

Technologies: Tenda TX9 Pro. Vendors: Tenda.

Executive brief

Tenda TX9 Pro routers are affected by a security flaw in the web management interface. By sending a specially crafted network request to change a device name, an attacker can cause the router to crash or become unresponsive. This results in a denial of service, disrupting internet connectivity for all connected users and requiring a manual restart to restore operations.

Technical details

A stack-based buffer overflow exists in the Tenda TX9 Pro V22.03.02.20 firmware within the 'httpd' binary. The vulnerability is located in the 'update_dev_name' function (called by 'sub_425964') inside 'libtd_server.so'. The root cause is improper bounds checking when converting the 'devName' POST parameter from GB2312 to UTF-8 using the 'gb2312_2_utf8' function. A remote attacker can exploit this by sending a long string in the 'devName' parameter to the '/goform/SetOnlineDevName' endpoint, leading to a crash of the web service or the entire device.

Affected products

  • Tenda TX9 Pro V22.03.02.20

Timeline

  • 2024-10-21: other: Initial vulnerability report and PoC published on Gitee
  • 2026-07-20: disclosed: CVE published to NVD dataset

References

Related threats